CVE-2009-1342: XSS
Cross-site scripting (XSS) vulnerability in the CCK comment reference module 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via certain comment titles associated with a node edit form.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1342?
CVE-2009-1342 is classified as a cross-site scripting (XSS) vulnerability which can potentially allow attackers to inject malicious scripts.
How do I fix CVE-2009-1342?
To resolve CVE-2009-1342, upgrade the CCK Comment Reference module to version 6.x-1.2 or later.
What versions of Drupal are affected by CVE-2009-1342?
CVE-2009-1342 affects the CCK Comment Reference module version 6.x before 6.x-1.2.
Can CVE-2009-1342 be exploited remotely?
Yes, CVE-2009-1342 can be exploited remotely by attackers through crafted comment titles.
What is the impact of CVE-2009-1342?
The impact of CVE-2009-1342 includes the potential for attackers to execute arbitrary web scripts in the context of affected users.